---
title: CSP Account Definition
slug: kronpam-reference-guide-3-5-0/csp-account-definition
docTags: 
createdAt: 2024-03-22T13:02:12.247Z
---

Cloud Service Provider’s account should be defined under the cloud integration section. AWS, Azure, and GCP are supported cloud service providers.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/0Vfhd1QrFWYilgkTcqlxq_image.png)

The permission list of the CSP account to be entered into PAM should be as follows:
•	IAM\_LIST\_USERS("IAM\:listUsers"),
•	IAM\_LIST\_INSTANCE\_PROFILES("IAM\:instanceProfiles"),
•	IAM\_LIST\_MFA\_DEVICES("IAM\:listMFADevices"),
•	IAM\_LIST\_GROUPS\_FOR\_USER("IAM\:listGroupsForUser"),
•	IAM\_LIST\_ATTACHED\_USER\_POLICIES("IAM\:listAttachedUserPolicies"),
•	IAM\_LIST\_ACCESS\_KEYS("IAM\:listAccessKeys"),
•	IAM\_GET\_ACCESS\_KEY\_LAST\_USED("IAM\:getAccessKeyLastUsed"),
•	IAM\_LIST\_ROLES("IAM\:listRoles"),
•	IAM\_LIST\_ATTACHED\_ROLE\_POLICIES("IAM\:listAttachedRolePolicies"),
•	IAM\_LIST\_ROLE\_POLICIES("IAM\:listRolePolicies"),
•	IAM\_LIST\_GROUPS("IAM\:listGroups"),
•	IAM\_LIST\_ATTACHED\_GROUP\_POLICIES("IAM\:listAttachedGroupPolicies"),
•	IAM\_LIST\_GROUP\_POLICIES("IAM\:listGroupPolicies"),
•	IAM\_LIST\_POLICIES("IAM\:listPolicies"),
•	S3\_LIST\_BUCKETS("S3\:listBuckets"),
•	S3\_GET\_BUCKET\_LOCATION("S3\:getBucketLocation")
•	S3\_LIST\_OBJECTS\_V2("S3\:listObjectsV2")
•	S3\_GET\_BUCKET\_ACL("S3\:getBucketAcl")
•	S3\_GET\_BUCKET\_CORS("S3\:getBucketCors")
•	S3\_GET\_BUCKET\_ENCRYPTION("S3\:getBucketEncryption")
•	S3\_GET\_BUCKET\_POLICY("S3\:getBucketPolicy")
•	S3\_GET\_BUCKET\_POLICY\_STATUS("S3\:getBucketPolicyStatus")
•	RDS\_DESCRIBE\_INSTANCES("RDS\:describeInstances")
•	RDS\_DESCRIBE\_INSTANCES\_ROLE("RDS\:describeInstancesRole")
•	EC2\_DESCRIBE\_INSTANCES("EC2\:describeInstances")
•EC2\_DESCRIBE\_INSTANCE\_ROLES("EC2\:describeIamInstanceProfileAssociations")
